Cometin Desktop
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v1.0.1.2
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
7 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall crypto operations Cryptographic operations detected | 2 | js/jquery-3.4.1.min.js_metadata/verified_contents.json | Risky Plugins Authors FP 30% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 4 | setup/setup.jsjs/jquery-3.4.1.min.jsdashboard/dashboard.js +1 more | FP 5% |
| HIGH | postinstall file manipulation File system manipulation detected | 17 | dashboard/dashboard.jssetup/setup.htmljs/jquery.dataTables.min.js +14 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 3 | utils.jsdashboard/help/help.htmljs/jquery-3.4.1.min.js | Risky Plugins Authors FP 10% |
| HIGH | postinstall network communication Network communication detected | 7 | background.jsdashboard/general_include.jsjs/jquery-3.4.1.min.js +4 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 6 | js/bootstrap.bundle.min.jsjs/jquery-3.4.1.min.jsjs/qrcode.min.js +3 more | Risky Plugins Authors FP 20% |
| HIGH | SQLInjection SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory. | 2 | js/bootstrap.bundle.min.jsjs/jquery-3.4.1.min.js | FP 10% |
Publisher Evidence
Limited evidenceStjin
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
7 rules(41 hits)AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality weak.
The Cometin Desktop extension presents an ambiguous security profile requiring further investigation. The extension claims to sync PC information with Cometin Cloud, and its network behavior aligns with this stated purpose. Network findings show jquery_ajax calls in background.js:14, background.js:61, background.js:178, dashboard/dashboard.js:15, dashboard/dashboard.js:167, dashboard/general_include.js:12, setup/setup.js:33, and multiple locations in dashboard/notes/notes.js (lines 28, 78, 137, 236, 292). These are legitimate synchronous HTTP calls consistent with a cloud sync extension's functionality.
However, 41 high-severity malware-signature findings create significant concern. The evidence bundle does not specify which YARA rules triggered these findings or what specific code patterns matched. This is a critical gap—without knowing whether these are actual malware signatures or broad false-positive rules (such as the reclassified Bolonyokte, JavaDropper, or Surtr rules that match benign patterns), the risk cannot be properly assessed.
Additional risk factors include: developer name "Stjin" is not a known or verified publisher; user count is 0 indicating no adoption or review history; and version is listed as "unknown" suggesting incomplete metadata collection. The extension claims to be "official" Cometin Desktop but Cometin is not a well-known service, making impersonation unverifiable.
The strongest counterargument for a benign verdict is that the network findings show no suspicious domains, no credential access patterns, no obfuscation, and no IoC matches—all network calls are standard jquery AJAX for cloud communication. A skeptic would argue that 41 malware signatures in a 0-user extension from an unknown developer represents clear malicious intent. However, without signature specificity, this conclusion cannot be drawn. The malware-signature findings could stem from bundled libraries triggering broad YARA rules, which would make this a false positive rather than actual malware.
Runtime analysis or manual code review is required to determine whether the malware-signature findings represent genuine threats or known false-positive patterns.
Key Reasons
- 41 high-severity malware-signature findings without specific rule details
- Unknown developer (Stjin) with 0 users and unknown version
- Network behavior appears benign (jquery AJAX for cloud sync)
- No obfuscation, no IoC matches, no suspicious domains detected
- Missing malware-signature specificity prevents definitive verdict
False Positive Considerations
- Malware-signature findings lack rule specificity
- May be triggered by bundled library patterns
Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 55%.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace